Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

gulp copied files are downloadables!! #328

Open
jrichardsz opened this issue Nov 10, 2020 · 1 comment
Open

gulp copied files are downloadables!! #328

jrichardsz opened this issue Nov 10, 2020 · 1 comment
Assignees
Labels
investigate Pending Work pending Pending Close. Respond priority Important
Milestone

Comments

@jrichardsz
Copy link
Contributor

gulp copies the entire source code of several js libraries. All of them are available :

https://i.ibb.co/h1Bb0Rd/Screenshot-from-2020-11-10-14-51-52.png

Is this ok?

I tried mapping just the required files in gulp and it works!!

@ryanlelek
Copy link
Owner

Generally not an issue as all these libraries are public through NPM.
The image you added does show potentially-sensitive information that NPM adds, such as location which can expose filepaths

I'll mark this as "take a look" to investigate

@ryanlelek ryanlelek self-assigned this Dec 25, 2020
@ryanlelek ryanlelek added pending Pending Close. Respond priority Important labels Dec 25, 2020
@ryanlelek ryanlelek added the investigate Pending Work label Aug 12, 2022
@ryanlelek ryanlelek added this to the v0.18.x milestone Feb 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
investigate Pending Work pending Pending Close. Respond priority Important
Projects
None yet
Development

No branches or pull requests

2 participants